CVE-2024-34750 Apache Tomcat DoS vulnerability in HTTP/2 connector

Disclosed: 2024-07-05 03:12:26 By devme4f To ibb
High
Vulnerability Details
Hello IBB team, i would like to submit a report about Apache Tomcat DoS vulnerability that i have reported to the Tomcat team, which was assigned to CVE-2024-34750 and disclosed yesterday. **Details:** When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn led to the use of an incorrect infinite timeout which allowed connections to remain open which should have been closed. **Here is the email thread that i contacted the security team:** ██████████ ## Impact Since HTTP/2 connections are left open indefinitely, depending on configuration the DoS is caused either by the server running out of memory or by the open connections reaching maxConnections.
Actions
View on HackerOne
Report Stats
  • Report ID: 2586226
  • State: Closed
  • Substate: resolved
  • Upvotes: 56
Share this report